CVE-2012-0451
Summary
| CVE | CVE-2012-0451 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-03-14 19:55:01 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | CRLF injection vulnerability in Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 allows remote web servers to bypass intended Content Security Policy (CSP) restrictions and possibly conduct cross-site scripting (XSS) attacks via crafted HTTP headers. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mozilla | Firefox | 10.0 | All | All | All |
| Application | Mozilla | Firefox | 4.0 | All | All | All |
| Application | Mozilla | Firefox | 4.0 | beta1 | All | All |
| Application | Mozilla | Firefox | 4.0 | beta10 | All | All |
| Application | Mozilla | Firefox | 4.0 | beta11 | All | All |
| Application | Mozilla | Firefox | 4.0 | beta12 | All | All |
| Application | Mozilla | Firefox | 4.0 | beta2 | All | All |
| Application | Mozilla | Firefox | 4.0 | beta3 | All | All |
| Application | Mozilla | Firefox | 4.0 | beta4 | All | All |
| Application | Mozilla | Firefox | 4.0 | beta5 | All | All |
| Application | Mozilla | Firefox | 4.0 | beta6 | All | All |
| Application | Mozilla | Firefox | 4.0 | beta7 | All | All |
| Application | Mozilla | Firefox | 4.0 | beta8 | All | All |
| Application | Mozilla | Firefox | 4.0 | beta9 | All | All |
| Application | Mozilla | Firefox | 4.0.1 | All | All | All |
| Application | Mozilla | Firefox | 5.0 | All | All | All |
| Application | Mozilla | Firefox | 5.0.1 | All | All | All |
| Application | Mozilla | Firefox | 6.0 | All | All | All |
| Application | Mozilla | Firefox | 6.0.1 | All | All | All |
| Application | Mozilla | Firefox | 6.0.2 | All | All | All |
| Application | Mozilla | Firefox | 7.0 | All | All | All |
| Application | Mozilla | Firefox | 7.0.1 | All | All | All |
| Application | Mozilla | Firefox | 8.0 | All | All | All |
| Application | Mozilla | Firefox | 8.0.1 | All | All | All |
| Application | Mozilla | Firefox | 9.0 | All | All | All |
| Application | Mozilla | Firefox | 9.0.1 | All | All | All |
| Application | Mozilla | Firefox Esr | 10.1 | All | All | All |
| Application | Mozilla | Firefox Esr | 10.2 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0 | alpha | All | All |
| Application | Mozilla | Seamonkey | 1.0 | beta | All | All |
| Application | Mozilla | Seamonkey | 1.0.1 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0.2 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0.3 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0.4 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0.5 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0.6 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0.7 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0.8 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0.9 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1 | alpha | All | All |
| Application | Mozilla | Seamonkey | 1.1 | beta | All | All |
| Application | Mozilla | Seamonkey | 1.1.1 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.10 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.11 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.12 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.13 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.14 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.15 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.16 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.17 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.18 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.19 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.2 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.3 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.4 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.5 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.6 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.7 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.8 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.9 | All | All | All |
| Application | Mozilla | Seamonkey | 1.5.0.10 | All | All | All |
| Application | Mozilla | Seamonkey | 1.5.0.8 | All | All | All |
| Application | Mozilla | Seamonkey | 1.5.0.9 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0 | alpha_1 | All | All |
| Application | Mozilla | Seamonkey | 2.0 | alpha_2 | All | All |
| Application | Mozilla | Seamonkey | 2.0 | alpha_3 | All | All |
| Application | Mozilla | Seamonkey | 2.0 | beta_1 | All | All |
| Application | Mozilla | Seamonkey | 2.0 | beta_2 | All | All |
| Application | Mozilla | Seamonkey | 2.0 | rc1 | All | All |
| Application | Mozilla | Seamonkey | 2.0 | rc2 | All | All |
| Application | Mozilla | Seamonkey | 2.0.1 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0.10 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0.11 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0.12 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0.13 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0.14 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0.2 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0.3 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0.4 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0.5 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0.6 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0.7 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0.8 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0.9 | All | All | All |
| Application | Mozilla | Seamonkey | 2.1 | All | All | All |
| Application | Mozilla | Seamonkey | 2.1 | alpha1 | All | All |
| Application | Mozilla | Seamonkey | 2.1 | alpha2 | All | All |
| Application | Mozilla | Seamonkey | 2.1 | alpha3 | All | All |
| Application | Mozilla | Seamonkey | 2.1 | beta1 | All | All |
| Application | Mozilla | Seamonkey | 2.1 | beta2 | All | All |
| Application | Mozilla | Seamonkey | 2.1 | beta3 | All | All |
| Application | Mozilla | Seamonkey | 2.1 | rc1 | All | All |
| Application | Mozilla | Seamonkey | 2.1 | rc2 | All | All |
| Application | Mozilla | Seamonkey | 2.2 | All | All | All |
| Application | Mozilla | Seamonkey | 2.2 | beta1 | All | All |
| Application | Mozilla | Seamonkey | 2.2 | beta2 | All | All |
| Application | Mozilla | Seamonkey | 2.2 | beta3 | All | All |
| Application | Mozilla | Seamonkey | 2.3 | All | All | All |
| Application | Mozilla | Seamonkey | 2.3 | beta1 | All | All |
| Application | Mozilla | Seamonkey | 2.3 | beta2 | All | All |
| Application | Mozilla | Seamonkey | 2.3 | beta3 | All | All |
| Application | Mozilla | Seamonkey | 2.3.1 | All | All | All |
| Application | Mozilla | Seamonkey | 2.3.2 | All | All | All |
| Application | Mozilla | Seamonkey | 2.3.3 | All | All | All |
| Application | Mozilla | Seamonkey | 2.4 | All | All | All |
| Application | Mozilla | Seamonkey | 2.4 | beta1 | All | All |
| Application | Mozilla | Seamonkey | 2.4 | beta2 | All | All |
| Application | Mozilla | Seamonkey | 2.4 | beta3 | All | All |
| Application | Mozilla | Seamonkey | 2.4.1 | All | All | All |
| Application | Mozilla | Seamonkey | 2.5 | All | All | All |
| Application | Mozilla | Seamonkey | 2.5 | beta1 | All | All |
| Application | Mozilla | Seamonkey | 2.5 | beta2 | All | All |
| Application | Mozilla | Seamonkey | 2.5 | beta3 | All | All |
| Application | Mozilla | Seamonkey | 2.5 | beta4 | All | All |
| Application | Mozilla | Seamonkey | 2.6 | All | All | All |
| Application | Mozilla | Seamonkey | 2.6 | beta1 | All | All |
| Application | Mozilla | Seamonkey | 2.6 | beta2 | All | All |
| Application | Mozilla | Seamonkey | 2.6 | beta3 | All | All |
| Application | Mozilla | Seamonkey | 2.6 | beta4 | All | All |
| Application | Mozilla | Seamonkey | 2.6.1 | All | All | All |
| Application | Mozilla | Seamonkey | 2.7 | beta1 | All | All |
| Application | Mozilla | Seamonkey | 2.7 | beta2 | All | All |
| Application | Mozilla | Seamonkey | 2.7 | beta3 | All | All |
| Application | Mozilla | Seamonkey | 2.7 | beta4 | All | All |
| Application | Mozilla | Seamonkey | All | beta5 | All | All |
| Application | Mozilla | Thunderbird | 5.0 | All | All | All |
| Application | Mozilla | Thunderbird | 6.0 | All | All | All |
| Application | Mozilla | Thunderbird | 6.0.1 | All | All | All |
| Application | Mozilla | Thunderbird | 6.0.2 | All | All | All |
| Application | Mozilla | Thunderbird | 7.0 | All | All | All |
| Application | Mozilla | Thunderbird | 7.0.1 | All | All | All |
| Application | Mozilla | Thunderbird | 8.0 | All | All | All |
| Application | Mozilla | Thunderbird | 9.0 | All | All | All |
| Application | Mozilla | Thunderbird | 9.0.1 | All | All | All |
| Application | Mozilla | Thunderbird Esr | 10.0 | All | All | All |
| Application | Mozilla | Thunderbird Esr | 10.0.1 | All | All | All |
| Application | Mozilla | Thunderbird Esr | 10.0.2 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Mozilla Seamonkey Multiple Bugs Let Remote Users Execute Arbitrary Code and Conduct Cross-Site Scripting Attacks - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| openSUSE-SU-2012:0417-1: moderate: update for MozillaFirefox, MozillaThu | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| USN-1400-5: GSettings desktop schemas regression | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| USN-1400-2: ubufox update | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| Security Alerts - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| USN-1400-1: Firefox vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| Security Alerts - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| [security-announce] SUSE-SU-2012:0424-1: critical: Security update for M | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Security Alerts - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| MFSA 2012-15: XSS with multiple Content Security Policy headers | af854a3a-2127-422b-91ae-364da2661108 | www.mozilla.org | |
| USN-1400-4: Thunderbird regressions | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| Mozilla Firefox/Thunderbird/SeaMonkey HTTP Header Security Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| USN-1400-3: Thunderbird vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| Security Alerts - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Mozilla Thunderbird Multiple Bugs Let Remote Users Execute Arbitrary Code and Conduct Cross-Site Scripting Attacks - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Security Advisory SA48359 - Red Hat update for thunderbird - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| 717511 – (CVE-2012-0451) Bad intersection of injected HTTP headers leads to Content Security Policy (CSP) Bypass | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| Mozilla Firefox Multiple Bugs Let Remote Users Execute Arbitrary Code and Conduct Cross-Site Scripting Attacks - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Security Alerts - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| mandriva.com | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| Security Alerts - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Security Advisory SA48561 - Pale Moon Multiple Vulnerabilities - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.